Apache Openoffice vulnerabilities
59 known vulnerabilities affecting apache/openoffice.
Total CVEs
59
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH27MEDIUM17
Vulnerabilities
Page 2 of 3
CVE-2010-3452P3CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-3452 [CRITICAL] CWE-416 CVE-2010-3452: Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remot
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
nvd
CVE-2010-4643P3CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-4643 [CRITICAL] CWE-787 CVE-2010-4643: Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote a
Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
nvd
CVE-2010-3453P3CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-3453 [CRITICAL] CWE-787 CVE-2010-3453: The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code vi
nvd
CVE-2009-3302P3CRITICALCVSS 9.3fixed in 3.2.02010-02-16
CVE-2009-3302 [CRITICAL] CWE-94 CVE-2009-3302: filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial
filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw."
nvd
CVE-2010-3451P3CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-3451 [CRITICAL] CWE-416 CVE-2010-3451: Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remot
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in an RTF document.
nvd
CVE-2012-2665P3HIGHCVSS 7.5fixed in 3.4.12012-08-06
CVE-2012-2665 [HIGH] CWE-787 CVE-2012-2665: Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in Ope
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a
nvd
CVE-2016-6804P3HIGHCVSS 7.8fixed in 4.1.32017-11-20
CVE-2016-6804 [HIGH] CWE-264 CVE-2016-6804: The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org)
The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated privileges. This requires that the location in which the installer is run has been previously poisoned by a file that impersonates a dynamic-link library that
nvd
CVE-2010-3454P3CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-3454 [CRITICAL] CWE-193 CVE-2010-3454: Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.o
Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
nvd
CVE-2011-2177P3HIGHCVSS 7.8v3.3.02019-11-27
CVE-2011-2177 [HIGH] CVE-2011-2177: OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the O
OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.
nvd
CVE-2022-47502P3HIGHCVSS 7.8≤ 4.1.132023-03-24
CVE-2022-47502 [HIGH] CWE-20 CVE-2022-47502: Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Se
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose.
Links can be activated by clicks, or by automatic document events.
The execution of such links must be subject to user approval.
In the affected versions of OpenOffice, approval for certain links is not
nvd
CVE-2022-38745P3HIGHCVSS 7.8fixed in 4.1.142023-03-24
CVE-2022-38745 [HIGH] CWE-94 CVE-2022-38745: Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class p
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
nvd
CVE-2021-41830P3HIGHCVSS 7.5fixed in 4.1.112021-10-11
CVE-2021-41830 [HIGH] CVE-2021-41830: It is possible for an attacker to manipulate signed documents and macros to appear to come from a tr
It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice advisory.
nvd
CVE-2015-5212P3MEDIUMCVSS 6.8≤ 4.1.12015-11-10
CVE-2015-5212 [MEDIUM] CWE-191 CVE-2015-5212: Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configura
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted PrinterSetup data in an ODF document.
nvd
CVE-2015-1774P3MEDIUMCVSS 6.8≤ 4.1.12015-04-28
CVE-2015-1774 [MEDIUM] CWE-787 CVE-2015-1774: The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.
nvd
CVE-2021-41832P3HIGHCVSS 7.5fixed in 4.1.112021-10-11
CVE-2021-41832 [HIGH] CVE-2021-41832: It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. A
It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory.
nvd
CVE-2020-13958P3HIGHCVSS 7.8≥ 4.0.0, < 4.1.82020-11-17
CVE-2020-13958 [HIGH] CVE-2020-13958: A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents cont
A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target users file system. These hyperlinks can be triggered unconditionally. In fixed versions no internal protocol may be called from the document event handler and other hyperlinks require a control-click.
nvd
CVE-2021-28129P3HIGHCVSS 7.8v4.1.82021-10-07
CVE-2021-28129 [HIGH] CWE-284 CVE-2021-28129: While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. Users who installed the Apache OpenOffice 4.1.8 DEB packagin
nvd
CVE-2008-3282P3HIGHCVSS 7.8v2.4.12008-08-29
CVE-2008-3282 [HIGH] CVE-2008-3282: Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory a
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability tha
nvd
CVE-2016-1513P3HIGHCVSS 7.8≤ 4.1.22016-08-05
CVE-2016-1513 [HIGH] CWE-125 CVE-2016-1513: The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of
The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted MetaActions in an (1) ODP or (2) OTP file.
nvd
CVE-2015-5213P3MEDIUMCVSS 6.8≤ 4.1.12015-11-10
CVE-2015-5213 [MEDIUM] CWE-189 CVE-2015-5213: Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attack
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.
nvd